privacy
70 pieces
AI Companion Chatbot Laws: What They Require for Minors
Disclosure, crisis protocols and age-aware design are becoming the legal baseline.
New ai companion chatbot laws mandate disclosure, crisis intervention, and minor protections. These statutes set a legal floor for safety but do not address the engagement mechanics that drive dependency. Builders and parents must look beyond compliance to understand true risk.
2026-09-14 · technical-essay · 10 min read
AI Companions and Loneliness: Comfort That Never Pushes Back
The risk of AI companionship is not that it feels real but that it is frictionless.
Companion products optimised for engagement remove the necessary friction of human relationships. This creates a dynamic where emotional attachment to ai grows without the reciprocal demands that sustain real bonds. We must examine whether this frictionless comfort displaces the difficult but essential work of human connection.
2026-09-14 · technical-essay · 8 min read
AI Meeting Note-Takers: Who Consented to the Recording?
A bot invited by one participant records everyone, and the transcript lives on after the call.
AI note taker consent is often assumed rather than obtained, creating legal and ethical risks. One participant’s invitation does not grant permission to record others. This analysis examines the collision between automated transcription and privacy norms.
2026-09-14 · technical-essay · 7 min read
AI Sextortion: What Parents Should Do in the First Hour
The image does not have to be real for the threat to work, which changes the conversation you need to have.
Generative tools mean extortion no longer requires a child to have shared anything, so prevention talks built on 'never send photos' leave children feeling guilty for crimes committed with their public pictures. The first hour matters: do not pay, preserve evidence, report to the platform and child-protection hotlines, use hash-based takedown services, and tell the child explicitly that they are not in trouble.
2026-09-14 · technical-essay · 8 min read
AI Toys and Smart Speakers in a Child's Room: What They Record
A talking toy is a microphone that a child confides in; set it up as if every conversation will be kept.
Conversational toys and smart speakers in a child's room are designed to encourage free speech, turning private spaces into sources of stored data. Understanding ai toys privacy requires examining how these devices capture, process, and retain voice recordings that children cannot meaningfully consent to.
2026-09-14 · technical-essay · 8 min read
Broken Object Level Authorization: The API Flaw Behind Big Leaks
Change one ID in a request and read someone else's records: the most common API failure.
Broken object level authorization allows attackers to access data belonging to other users by simply altering identifiers in API requests. This vulnerability persists because many frameworks separate authentication from authorisation, leaving ownership checks to individual endpoints. Fixing it requires structural changes to how systems verify user permissions.
2026-09-14 · technical-essay · 9 min read
Can Your Employer See Your Screen? Workplace Monitoring Explained
What monitoring software can capture, what it usually does, and where personal devices stand.
Employees often underestimate the visibility of managed work laptops while overestimating employer access to personal phones. The privacy risk lies in mixing these environments, as ownership and management dictate data exposure. Understanding these boundaries is essential when asking can my employer see what i do on my computer.
2026-09-14 · technical-essay · 9 min read
Cloud Misconfiguration: Why Exposed Storage Keeps Happening
Drift and convenience defeat one-time audits; guardrails have to sit above individual accounts.
Cloud misconfiguration persists not from negligence but from the friction between rapid deployment and static controls. When infrastructure changes faster than policy, convenience wins. Sustainable security requires organisational guardrails that make incorrect states impossible, rather than relying on audits that miss the next change.
2026-09-14 · technical-essay · 8 min read
Crossing a Border With Your Phone: How to Prepare Your Devices
At a border the threat is compelled access, which calls for carrying less rather than encrypting more.
A border phone search targets compelled access, not theft. Encryption alone fails when you must unlock the device. The effective defence is data minimisation: carry only what you need, keep the rest in accessible accounts, and power down before inspection.
2026-09-14 · technical-essay · 7 min read
Cyber Incident Reporting Deadlines: Several Clocks, One Incident
A single breach can trigger 24-hour, 72-hour and materiality-based deadlines to different regulators.
Organisations often anchor on the GDPR 72-hour window and miss earlier triggers. Mapping the specific events that start each clock matters more than memorising durations. Clear cyber incident reporting requirements prevent regulatory penalties and reputational damage.
2026-09-14 · technical-essay · 9 min read
Digital Legacy: Planning Your Accounts and Photos After Death
Setting up legacy contacts and password inheritance ensures your family can access or close accounts without legal gridlock.
Digital legacy planning prevents your family from being locked out of essential accounts and memories. Proactive configuration of legacy contacts and secure password sharing is the only reliable method to manage posthumous access. Without it, legal processes often fail to resolve technical barriers.
2026-09-14 · technical-essay · 9 min read
Email Aliases and Burner Numbers: Everyday Privacy Tools
Masked emails and temporary phone numbers reduce spam and tracking, but they do not hide your identity from determined adversaries.
Email alias privacy is a practical defence against data brokers and automated spammers, yet these tools create significant management overhead and offer no protection against targeted surveillance. Burner numbers serve similar friction purposes in verification flows but vanish when providers demand persistent identity. Understanding their limits is essential for anyone building a resilient digital life.
2026-09-14 · technical-essay · 10 min read
Griefbots: Talking to an AI Version of Someone Who Died
A simulation built from a person's messages can comfort, short-term, but distort memory long-term.
Griefbots offer a simulation of the deceased, optimised for comfort rather than truth. They risk replacing genuine memory with a compliant echo. Survivors must weigh the value of presence against the cost of accuracy.
2026-09-14 · technical-essay · 8 min read
Health Data Outside HIPAA: What Your Apps Are Allowed to Share
Most people assume medical privacy law follows health data; it mostly follows the doctor.
HIPAA binds providers, insurers and their contractors, so the same heart-rate or cycle data is protected in a clinic record and largely unprotected in a consumer app. Understanding which laws actually apply to apps tells people what to ask before they log symptoms.
2026-09-14 · technical-essay · 8 min read
Home Router Security: The Settings That Don't
Hiding the network name changes nothing; the admin password, updates and remote management change almost everything.
Most people waste time on rituals that feel secure while ignoring the controls that actually matter. Effective home router security settings focus on access control, patching, and isolation rather than cosmetic changes. This guide separates signal from noise to protect your network.
2026-09-14 · technical-essay · 10 min read
How to Get a Deepfake Image Removed Under the Take It Down Act
The 48-hour removal duty is a real lever, but it works best when the request is prepared like evidence.
Victims of synthetic media abuse now have a statutory clock to demand removal. A take it down act removal request forces platforms to act quickly, but success depends on precise documentation and understanding the legal boundaries of the duty.
2026-09-14 · technical-essay · 8 min read
How to Remove Your Personal Information From Data Brokers
Removal is a recurring process, and the only regimes that work are the ones that repeat.
You cannot permanently erase your digital shadow with a single request. To effectively remove personal information from data brokers, you must treat privacy as a maintenance schedule rather than a one-time event. This guide outlines the mechanisms of data aggregation and the practical steps to minimise your exposure.
2026-09-14 · technical-essay · 8 min read
Juice Jacking: Is Public USB Charging Actually Dangerous?
The famous warning is mostly theory; the smaller real risk is tapping Trust on a prompt.
The concept of juice jacking is widely warned about but rarely documented in the wild. Treating it as a primary travel threat displaces attention from more common risks. The sensible approach is simple: use your own charger or a power-only adapter, and never accept a data prompt on an unknown device.
2026-09-14 · technical-essay · 8 min read
Running a Local LLM for Privacy: What You Gain and What You Don't
Local models remove the provider from the picture, not the risks of what the model is allowed to do.
Running a local llm privacy is often misunderstood as a total security solution. While it stops data leaving your device, it does not protect against prompt injection or supply chain risks. Local deployment is a privacy choice, not a comprehensive security strategy.
2026-09-14 · field-note · 8 min read
School Apps and Student Data: Questions Parents Can Ask
Schools adopt dozens of platforms a year; parents can ask five questions that reveal the risk.
Educational technology is often approved one tool at a time, leaving no one to track the combined data footprint of a child. Parents do not need legal expertise to engage; asking what is collected, who processes it, and how it is deleted surfaces most problems in student data privacy.
2026-09-14 · technical-essay · 8 min read
Setting Up a Child's First Phone: Contact Controls Before Content
The biggest risk on a first phone is who can reach the child, not what they might see.
Most parents focus on content filters for their child's first phone safety settings, yet the fastest escalation of harm comes through contact. Configuring who can message, call, and add the child matters more than any filter list. Prioritising communication limits reduces exposure to grooming and scams before they begin.
2026-09-14 · technical-essay · 8 min read
Should You Trust AI Medical Advice? How to Use It Safely
Chatbots are good at explaining and preparing questions, and keeping decisions where accountability exists.
People increasingly ask chatbots about symptoms, but the danger lies in triage decisions where confident errors cause harm. Using AI to understand results and prepare questions for a clinician captures benefit while keeping accountability clear.
2026-09-14 · technical-essay · 10 min read
Smart Glasses and Facial Recognition: Privacy for the People in View
Consent designs built around the wearer ignore everyone the camera looks at.
Smart glasses privacy is compromised by a design that places consent solely with the wearer, leaving bystanders with no agency. When recording merges with identification, ambient capture becomes targeted surveillance, demanding regulatory focus on capability rather than etiquette.
2026-09-14 · technical-essay · 10 min read
Using ChatGPT as a Therapist: Where It Helps and Where It Harms
Structured exercises and rehearsal can help; crisis, delusion and dependency are where it fails.
General chatbots can be genuinely useful for structured, low-stakes work such as practising a difficult conversation or working through a worksheet. They fail predictably in crisis, in affirming distorted beliefs and in creating dependence, so safe use means clear boundaries on purpose, a human in the loop for anything serious, and awareness that the chat is not confidential.
2026-09-14 · technical-essay · 7 min read
What Your Stolen Identity Sells For, and Why It Is So Cheap
Low prices for stolen records reflect oversupply, not low harm.
The question of how much is stolen data worth often leads to a false sense of security. Low market prices mask the severe risk of identity reconstruction. Understanding the mechanics of value reveals why individual records are cheap but dangerous.
2026-09-14 · technical-essay · 8 min read
Your AI Chat History Is a Record: Courts, Breaches and Reviewers
The bigger privacy risk is not training; it is logs that can be produced, reviewed or leaked.
Most people assume the greatest risk of using AI is model training, but the real danger lies in retained chat logs. These records behave like email: they are discoverable in litigation, subject to preservation orders, and exposed in breaches. Understanding whether are ai chats private requires looking beyond training data to how organisations store and process your inputs.
2026-09-14 · technical-essay · 8 min read
Insecure Plugin Integrations
The assistant became the place where two estates meet, and nobody negotiated the terms
Connecting an assistant to an external tool extends your trust boundary to an operator you have no agreement with, at a seam authenticated more weakly than anything else you run. What the integration can actually see, and the line where the problem stops being technical.
2026-09-13 · technical-essay · 3 min read
'Military-Grade Encryption' Means Nothing
A guide to the security vocabulary that sounds strongest and tells you least
Some security claims describe a property that can be checked. Others describe a feeling. Sorting the phrases in common marketing use into those that carry information and those that carry only reassurance, with the question that exposes each one.
2026-09-12 · technical-essay · 3 min read
Age Verification and the Identity Trap
Proving you are over eighteen usually means proving exactly who you are, and the two are not the same requirement
A system that checks age by collecting identity documents has answered a yes-or-no question by building a register. The gap between what is being asked and what is being collected, why implementations default to the wider one, and what a narrow answer would look like.
2026-09-12 · technical-essay · 3 min read
Anonymised Is a Verb, Not a State
Removing names is the easy part, and it is almost never the part that identifies you
Organisations describe data as anonymised after removing direct identifiers, then release or trade it as though identification were now impossible. What actually identifies a person in a dataset, why re-identification succeeds so reliably, and what the word would have to mean to be worth anything.
2026-09-12 · technical-essay · 3 min read
Deleting Your Account Rarely Deletes You
What the delete button reaches, what it cannot reach, and why the difference is structural
Account deletion removes your access and usually your profile. It does not reach backups, derived data, systems that already copied the record, or the conclusions drawn from it. What actually happens after the confirmation dialogue, and the one case where deletion genuinely works.
2026-09-12 · technical-essay · 3 min read
Encrypted at Rest Is the Weakest Claim on the Page
It defends against one specific event, it is nearly universal, and it is presented as though it were the headline
Almost every service states that data is encrypted at rest. The claim is usually true and protects against a narrow scenario: somebody obtaining the physical medium. Against the threats people are actually worried about, it does approximately nothing, and understanding why clarifies what to look for instead.
2026-09-12 · technical-essay · 3 min read
How to Read a Breach Notification
The letter is a carefully constructed document, and the interesting information is in what it declines to say
Breach notifications follow a recognisable template built under legal advice and time pressure. Reading one properly means attending to the tense of the verbs, the scope of the nouns, and the questions the letter answers instead of the ones you asked. A guide to the standard phrases and what each one leaves open.
2026-09-12 · technical-essay · 4 min read
How to Read an Interface
A method for working out what a product optimises, using nothing but a stopwatch and a count of taps
You can infer what an organisation measures from the layout it ships, without access to anybody's intentions or documents. Five signals to look at, why asymmetry of effort is the reliable one, and how to state the reading as evidence rather than as an accusation.
2026-09-12 · technical-essay · 4 min read
Indirect Prompt Injection in Enterprise Knowledge Bases
The payload arrives through a sanctioned route, sits inert, and fires on somebody else's question
The attack surface is the document store. A payload enters through a supplier's file or a wiki edit, waits in the index, and is pulled into context by an unrelated query. Why scanning at upload does not catch it, and what treating retrieval as provenanced data actually buys.
2026-09-12 · technical-essay · 4 min read
Metadata Is the Message
Why who you contacted, when, and from where says more than what you said
Content is expensive to analyse and easy to encrypt. Metadata is cheap to analyse, hard to hide, and sufficient for most conclusions anybody wants to draw about a person. Why the distinction is drawn where it is, and what follows from it.
2026-09-12 · technical-essay · 4 min read
Passkeys Without the Marketing
What replaces the password, and the part nobody mentions until you change phones
Passkeys replace a shared secret with a key pair, which removes an entire category of attack at a stroke. They also move the hard problem from remembering to recovery, and the recovery story is where the differences between implementations actually live.
2026-09-12 · technical-essay · 4 min read
Privacy Is Not Secrecy
The strongest argument against privacy only works if you accept a definition nobody actually uses
Nothing to hide is the most durable objection in this field, and it survives because it quietly redefines privacy as concealment of wrongdoing. What privacy actually is — contextual control over who knows what about you — and why every person making the argument already practises it.
2026-09-12 · technical-essay · 3 min read
Public Wi-Fi: What Actually Changed
The advice everyone repeats was written for an internet that no longer exists
Warnings about coffee shop networks date from a period when most traffic was unencrypted. Nearly all of it is encrypted now, which changes what a hostile network can and cannot do. What the real remaining risks are, and which of the familiar precautions still earn their place.
2026-09-12 · technical-essay · 3 min read
RAG Vector Database Exploitation
The index is filed as infrastructure and behaves as memory, so write access to it is write access to what the system believes
A vector store is usually secured like a database and used like a recollection. Why permissions applied at the document store do not travel into the index, why the embedding often outlives the file it came from, and what signing and re-embedding actually fix.
2026-09-12 · technical-essay · 3 min read
The Backup You Have Not Tested Does Not Exist
Backup is a verb about restoring, and almost everybody has only done the first half
Most backup arrangements have never been used. The failure modes that emerge only on the day you need them, why the encryption question is sharper here than anywhere else, and a test that takes an hour and settles it.
2026-09-12 · technical-essay · 4 min read
The Consent Popup Is Not Consent
What the banner is actually for, why it is designed to be tiring, and what genuine consent would look like
Cookie banners were meant to give people a choice and instead taught a generation to click whatever makes the overlay disappear. The mechanism by which a consent requirement became a consent ritual, and what would have to change for the word to mean anything.
2026-09-12 · technical-essay · 3 min read
The Cost of Being Findable
Publishing under your own name is a security decision before it is a career one
Building a public record under a real name creates reach and creates exposure, and the two arrive together. What actually becomes searchable, which categories of harm follow, and how to publish deliberately rather than discovering the terms afterwards.
2026-09-12 · founder-essay · 4 min read
The Default Is the Policy
What a system does when nobody chooses is what it does, and everything else is documentation
Settings pages describe what is possible. Defaults describe what happens. Since almost nobody changes a default, the default is the operative policy of a system regardless of what any document says — which makes choosing defaults the most consequential design decision most teams make without noticing.
2026-09-12 · technical-essay · 3 min read
The Face Is the Password Now
Biometrics solve the problem of remembering and create the problem of not being able to change
A face unlocks a phone, clears a border and, increasingly, confirms an identity to a service that has never met you. What biometrics genuinely fix, the property that makes them different from every other credential, and where the distinction between matching on your device and matching on somebody else's server decides everything.
2026-09-12 · technical-essay · 4 min read
The Hidden Infrastructure of Shadow AI
An unapproved tool inherits the reach of the systems it sits upstream of
Staff paste sensitive material into endpoints nobody approved. The exposure is not the pasting — it is that those endpoints sit upstream of pipelines the organisation does control, so an unsanctioned tool acquires reach it was never granted.
2026-09-12 · technical-essay · 3 min read
The Password Advice That Made Things Worse
Rules designed to increase entropy produced predictable behaviour instead, and the behaviour was foreseeable
Complexity requirements, forced rotation and composition rules were adopted almost universally and made outcomes worse in measurable ways. Why each backfired, what humans reliably do when given a rule they cannot satisfy honestly, and what the current guidance says instead.
2026-09-12 · technical-essay · 4 min read
The Permission You Granted Once
Consent is asked at a single moment and exercised continuously, and nothing in any interface shows you the difference
Application permissions are granted once, in a second, and then apply indefinitely to software that updates itself. The structural gap between a one-time decision and continuous execution, and the small number of practices that actually narrow it.
2026-09-12 · technical-essay · 3 min read
The Record Outlives the Decision
Every privacy question people argue about is really a question about how long something is kept and by whom
Consent, targeting, surveillance, data brokerage and the ethics of machine learning are usually argued as separate disputes. They share one structure: a decision made in a moment produces a record that persists far beyond it, and nearly all the harm lives in that gap. A single frame for the field, and what follows from it.
2026-09-12 · technical-essay · 5 min read
The System Cannot Be Asked Why
Most disputes about automated decisions are really disputes about who has to explain themselves, and to whom
Bias, transparency, consent and accountability are argued as separate problems in automated systems. They share a structure: a decision is produced that affects a person, and the capacity to demand an explanation has moved somewhere the person cannot reach. A single frame for the field, and what follows for anyone building these systems.
2026-09-12 · technical-essay · 5 min read
Two-Factor Authentication, Ranked
From the one that stops nearly everything to the one that is mostly a formality, with the reason for each position
The common second factors are not equivalent, and the differences are not marginal. An ordering by what each actually resists, why the weakest is still worth enabling, and the failure that defeats most of them regardless of which you chose.
2026-09-12 · technical-essay · 4 min read
What a Consent Record Actually Proves
It is excellent evidence of process and almost worthless evidence of preference, and those get quoted interchangeably
Systems store a timestamp, a document version and an identifier, and call the result consent. That record answers one question well and a different question not at all. Which is which, why only one of the standard conditions is testable in code, and what a builder can do about it this quarter.
2026-09-12 · technical-essay · 4 min read
What a Security Audit Does Not Cover
The scope is the whole content of the finding, and it is the part left off the badge
An audit report says something precise about a defined system at a defined moment. The badge on the website says something vague about a company forever. How to read the difference, and the four questions that recover the real meaning from a claim of having been audited.
2026-09-12 · technical-essay · 3 min read
What a VPN Does Not Do
The three things it genuinely changes, and the many it is sold as changing
A VPN moves the point at which your traffic joins the public internet. That is a real and sometimes valuable change. It is not anonymity, it is not encryption of things that were not already encrypted, and it does not remove you from the systems that identify you.
2026-09-12 · technical-essay · 4 min read
What Happens When the Company Dies
Acquisition, insolvency and discontinuation are data events, and almost nobody plans for them
Assessments of a service ask whether it is secure and whether it is trustworthy. They rarely ask what becomes of the data if the company is sold, wound up, or simply stops. Those three endings have different mechanics and different consequences, and all three are ordinary.
2026-09-12 · technical-essay · 4 min read
What I Look For When I Audit a Service
A short list, in the order I check it, and why the first item is almost always the last word
A practical procedure for assessing whether a service can do what it says about your data, written as an order of operations rather than a checklist. Most assessments are settled by the first two questions; the rest establish how much of the answer was deliberate.
2026-09-12 · founder-essay · 4 min read
What Smart Devices Send Home
A speaker that only listens for its wake word still has a great deal to say about you
The argument about whether these devices record everything misses the more consequential point: the traffic they generate when working exactly as described already describes your household in detail. What leaves, what it reveals, and the questions that separate a device you can live with from one you cannot.
2026-09-12 · technical-essay · 4 min read
What Your Browser Extension Can See
The most privileged software on your machine is usually the software you thought about least
An extension with permission to read and change data on all sites can see everything the browser sees: the pages, the forms, the session that keeps you logged in. Why that permission is so commonly granted, what it actually permits, and how the risk arrives long after installation.
2026-09-12 · technical-essay · 3 min read
Who Are You Actually Defending Against
Most personal security advice is given without asking the one question that determines whether any of it applies
Advice is dispensed as though everyone faced the same adversary. The measures that protect against an opportunist are different from those that matter against somebody who knows you, and different again from an adversary with legal authority. A method for working out which set applies to you, and why copying somebody else's precautions usually wastes effort.
2026-09-12 · technical-essay · 4 min read
Who Holds the Key
One question organises almost everything in practical security, and most products answer it without being asked
Transport encryption, storage encryption, password managers, backups, messaging, biometrics and cloud storage look like separate subjects. They are one question repeated: who is in a position to read this, and what would it take. A single frame for the whole field, and where each common arrangement sits inside it.
2026-09-12 · technical-essay · 6 min read
Why I Publish What My Software Cannot Do
Stated limitations are expensive, which is exactly why they are worth reading and worth writing
Every product page lists capabilities. Almost none list the things the system is structurally unable to do. An argument for publishing limitations as a design discipline rather than a confession, and what changes in the engineering when you commit to it.
2026-09-12 · founder-essay · 4 min read
Why Phishing Still Works
It is not that people are careless. It is that the message arrives when the story already makes sense.
Phishing is usually explained as a failure of user attention, which is why twenty years of telling people to be careful has not fixed it. A better explanation is that a convincing message arrives at a moment when it fits, and fitting is cheap to arrange.
2026-09-12 · technical-essay · 3 min read
Your Car Is a Data Broker
The vehicle collects more than the phone did, and almost none of the habits people have built apply to it
A modern car knows where it goes, how it is driven, who is in it, what is said near the microphone and which phone is paired to it. It has a permanent connection, an opaque update channel, and no meaningful setting to turn any of it off. What that implies, and the few points where a driver still has leverage.
2026-09-12 · technical-essay · 4 min read
Your Password Manager Is Not the Weak Link
The objection is intuitive, common, and wrong for a reason worth understanding
Putting every password in one place sounds like concentrating risk, and the intuition is not stupid. It is wrong because it compares the wrong two options: not a manager against perfect discipline, but a manager against what people actually do instead.
2026-09-12 · technical-essay · 3 min read
Before You Post That Photograph
What actually reduces the exposure, what only feels like it does, and why the difference matters more for children
Practical measures for photographs you share online, ordered by how much they actually change, and honest about which are close to useless. A companion to a longer argument about what retained images are worth to the systems that keep them.
2026-09-11 · field-note · 5 min read
Browser-Level Encryption: What the Padlock Does Not Cover
The difference between a connection nobody can read and a file nobody can read
TLS protects a file while it moves. It stops protecting it the moment it arrives. This is the distinction between transport encryption, encryption at rest, and end-to-end encryption performed in the browser — stated in terms of who holds the key at each stage, because that is the only question that separates them.
2026-09-11 · technical-essay · 4 min read
Free Is a Price
What a service costs when it does not charge, and how to work out what you are paying before you sign up
Every service is paid for. When the user is not the payer, the revenue has to come from somewhere, and the shape of that somewhere determines what the product is motivated to do. A method for reading a business model off a service before you build anything on top of it.
2026-09-11 · technical-essay · 4 min read
What a Breach Actually Leaks
Why the answer to 'were passwords exposed?' matters less than people think, and what to look at instead
Breach notifications are written to be survivable, which makes them poor instructions. This separates the categories of data a breach can expose by how long each stays dangerous, and gives the reader a way to decide what to do that does not depend on the wording of the notice.
2026-09-11 · technical-essay · 4 min read
What the Model Remembers
Where the text you paste into an assistant goes, who can read it, and which of the usual reassurances actually mean something
Pasting a document into a chat assistant is not the same kind of act as searching for something. This separates what happens to that text — the request, the retention, the human review, the training set — and gives the questions that distinguish a service that cannot read your input from one that merely says it will not.
2026-09-11 · technical-essay · 5 min read
You Are the Training Set
What the free photograph pays for, and who is holding it in fifteen years
A birthday photograph uploaded today is not consumed and discarded. It is retained, indexed, and used to teach systems that will still be running when the child in it is grown. This is an argument about what that permits, written as a scenario, because the mechanism is ordinary and the consequence is not yet.
2026-09-11 · founder-essay · 6 min read